PolicyOpen source DeepSeek

Chinese state hackers more than doubled their attacks after adopting DeepSeek

Rows of identical terminals in a dark room, the foreground monitor showing the DeepSeek mark

The AI safety debate is mostly about frontier models. The model showing up in incident reports is the cheap one anyone can download.

What TeamT5 found

Taiwanese research firm TeamT5 told Bloomberg on August 24, 2026 that state-affiliated Chinese groups have more than doubled the volume of attacks they run since they began handing routine work to open-source AI models and using them to develop malicious software.

The model they reach for is DeepSeek. “DeepSeek is the AI of choice for Chinese hackers because it’s relatively powerful with very low cyber guardrails,” said TeamT5 chief analyst Charles Li. Its popularity in the country also rests on strong performance and the ability to customise it locally.

Specific uses in the report

Bloomberg’s account of the findings names three groups and what each did with the model. Grimfengxi used it to write exploit code. Huapi used a Chinese model, likely DeepSeek, against a Taiwanese company’s email system. Teleboyi used it to collect 1,000 IP addresses from the internet and map a target’s domains.

Researchers add a detail worth noting: they have not yet caught a pricier model such as Kimi K3 being used in an attack.

Why volume is the metric

None of these tasks are novel capabilities. Writing exploit code, enumerating infrastructure and phishing an email system are things these groups already did. What changed is the cost per operation. When the boring middle of an intrusion becomes cheap, the same headcount runs more operations, and that is exactly what the counts show.

The UK’s AI Security Institute warned in May 2026 that the cyber capabilities of models are doubling every few months. The attack numbers are now doubling alongside them.

The policy gap

Safety cases, red-teaming commitments and staged deployment all apply to models a lab controls. A downloadable model with light guardrails sits outside that entire apparatus. The uncomfortable finding here is not that a powerful model can be misused, but that the cheap one already is, at scale, and there is no deployment lever to pull.

Sources

ANOTHER News is published by ANOTHER, an AI-native content agency. Daily coverage also runs on Instagram.